SecurityTracker.com
    Home    |    View Topics    |    Search    |    Contact Us    |   

SecurityTracker
Archives


 


Category:   Application (Security)  >   Network Security Services (NSS) Vendors:   Mozilla.org
(CentOS Issues Fix for Network Security Services (NSS)) Mozilla Firefox Multiple Flaws Let Remote Users Execute Arbitrary Code, Spoof the Address Bar, Overwrite Files, and Deny Service
SecurityTracker Alert ID:  1035484
SecurityTracker URL:  http://securitytracker.com/id/1035484
CVE Reference:   CVE-2016-1979   (Links to External Site)
Date:  Apr 5 2016
Impact:   Denial of service via network, Execution of arbitrary code via network, Modification of system information, Modification of user information, User access via network
Fix Available:  Yes  Vendor Confirmed:  Yes  

Description:   Multiple vulnerabilities were reported in Mozilla Firefox. A remote user can cause arbitrary code to be executed on the target user's system. A remote user can cause denial of service conditions on the target system. A remote user can modify files on the target system. A remote user can bypass same-origin restrictions on the target system. A remote user can spoof the address bar. Network Security Services (NSS) is affected.

A remote user can create specially crafted content that, when loaded by the target user, will execute arbitrary code on the target user's system [CVE-2016-1952, CVE-2016-1953].

A remote user can create specially crafted HTML that, when loaded by the target user, will overwrite files on the target user's system with a Content Security Policy (CSP) violation report [CVE-2016-1954].

A remote user may be able to obtain full path information for cross-origin iframe navigations in a CSP violatin report [CVE-2016-1955].

A remote user can create content that, when loaded by the target user, will perform certain WebGL operations in a canvas to consume excessive memory resources on the target user's system [CVE-2016-1956]. Certain Intel drivers on Linux are affected.

A remote user can create a specially crafted MPEG4 video file that, when loaded by the target user, will trigger a memory leak in the libstagefright library [CVE-2016-1957].

A remote user can spoof the address bar URL [CVE-2016-1958].

A remote user can trigger a flaw in the Clients API in Service Workers to cause an out-of-bounds read in ServiceWorkerManager and potentially execute arbitrary code [CVE-2016-1959].

A remote user can trigger a use-after-free memory error in the HTML5 string parser and potentially execute arbitrary code [CVE-2016-1960].

A remote user can trigger a use-after-free memory error in the SetBody function of HTMLDocument and potentially execute arbitrary code [CVE-2016-1961].

A remote user can trigger a use-after-free memory error when using multiple WebRTC data channel connections and potentially execute arbitrary code [CVE-2016-1962].

A local user can modify a file being read by FileReader to potentially execute arbitrary code [CVE-2016-1963].

A remote user can trigger a use-after-free memory error during XML transformation operations and potentially execute arbitrary code [CVE-2016-1964].

A remote user can spoof the address bar using location.protocol and history.back [CVE-2016-1965].

A remote user may be able to read cross-origin URLs [CVE-2016-1967].

A remote user can trigger a buffer overflow in the Brotli library and potentially execute arbitrary code [CVE-2016-1968].

A remote user can trigger a pointer dereference in the Netscape Plugin Application Programming Interface (NPAPI) plug-in and potentially execute arbitrary code [CVE-2016-1966].

A remote user can trigger memory errors in WebRTC and potentially execute arbitrary code [CVE-2016-1970, CVE-2016-1971, CVE-2016-1975, CVE-2016-1976, CVE-2016-1972].

A remote user can trigger a race condition in WebRTC in GetStaticInstance() and potentially execute arbitrary code [CVE-2016-1973].

A remote user can trigger an out-of-bounds memory read error in parsing unicode strings and potentially execute arbitrary code [CVE-2016-1974].

A remote user can create a specially crafted ASN.1 encoded certificate that, when parsed by the Network Security Services (NSS) library, will trigger a heap overflow and potentially execute arbitrary code [CVE-2016-1950].

A remote user can trigger a use-after-free memory error in the NSS libraries when processing DER-encoded keys [CVE-2016-1979].

A remote user can create a specially crafted graphite font that, when loaded by the target user, will trigger a stack corruption, uninitialized memory, out-of-bounds read, or out-of-bounds write error and potentially execute arbitrary code [CVE-2016-1969, CVE-2016-1977, CVE-2016-2790, CVE-2016-2791, CVE-2016-2792, CVE-2016-2793, CVE-2016-2794, CVE-2016-2795, CVE-2016-2796, CVE-2016-2797, CVE-2016-2798, CVE-2016-2799, CVE-2016-2800, CVE-2016-2801, CVE-2016-2802].

Bob Clary, Christoph Diehl, Christian Holler, Andrew McCreight, Daniel Holbert, Jesse Ruderman, Randell Jesup, Carsten Book, Gian-Carlo Pascutto, Tyson Smith, Andrea Marchesini, Jukka Jylanki, Nicolas Golubovic, Muneaki Nishimura (nishimunea) of Recruit Technologies Co.,Ltd., Ucha Gobejishvili, Jose Martinez, Romina Santillan,
Abdulrahman Alqabandi, Looben Yang, ca0nguyen (via HP's Zero Day Initiative), lokihardt (via HP's Zero Day Initiative), Dominique Hazael-Massieux, Oriol, Nicolas Gregoire, Tsubasa Iinuma, Jordi Chancel, Luke Li, the Communications Electronics Security Group (UK) of the GCHQ, Ronald Crane, Francis Gabriel, Tim Taubert, Holger Fuhrmannek, and James Clawson reported these vulnerabilities.

Impact:   A remote user can create content that, when loaded by the target user, will execute arbitrary code on the target user's system.

A remote user can cause denial of service conditions.

A remote user can overwrite files on the target system.

A remote user can bypass same-origin restrictions on the target system.

A remote user can spoof the address bar.

Solution:   CentOS has issued a fix for CVE-2016-1979 for Network Security Services (NSS).

i386:
5c8974b2d8730e2967751f835f4646bdf46fa968c29769748219ad426c5140d3 nss-3.21.0-0.3.el6_7.i686.rpm
f3782c46dfadef016d7afe8d81015c92ca5062e738d225377bfb38904e70708d nss-devel-3.21.0-0.3.el6_7.i686.rpm
32b9c62453b3dd45c60985751e36ed30aba93ea2f024b4b08443b7b9438eb5a8 nss-pkcs11-devel-3.21.0-0.3.el6_7.i686.rpm
7ee7fb2e4107b38d7c03677abb588fdd59b28459fa01a67f1a0bfb159295c688 nss-sysinit-3.21.0-0.3.el6_7.i686.rpm
a24d41eaadacaebcab9e7bf5490dc75028d7360e8484d9f4615b480067299539 nss-tools-3.21.0-0.3.el6_7.i686.rpm

x86_64:
5c8974b2d8730e2967751f835f4646bdf46fa968c29769748219ad426c5140d3 nss-3.21.0-0.3.el6_7.i686.rpm
7242d7e199b316736c10a1e97629001a3f2ab4ba540f0e313730ae8a11358544 nss-3.21.0-0.3.el6_7.x86_64.rpm
f3782c46dfadef016d7afe8d81015c92ca5062e738d225377bfb38904e70708d nss-devel-3.21.0-0.3.el6_7.i686.rpm
24a8bfae413d2a0ea8063fe0045615096d0cff4e8ddb483b625f32a20c403fb4 nss-devel-3.21.0-0.3.el6_7.x86_64.rpm
32b9c62453b3dd45c60985751e36ed30aba93ea2f024b4b08443b7b9438eb5a8 nss-pkcs11-devel-3.21.0-0.3.el6_7.i686.rpm
dc1976aceb5f1e49dcb95308bc6ae80e9100d759141308f5fb786ac6d49e65b3 nss-pkcs11-devel-3.21.0-0.3.el6_7.x86_64.rpm
99a95ba3bfebf8d62f4033b0578ff4c0a604becc5e5255700d98ccf305e68cc9 nss-sysinit-3.21.0-0.3.el6_7.x86_64.rpm
f1af7ca96a93c1ebeeab8051f137e92116d869ba0aa55c28bf7a6d0bcf7b49e7 nss-tools-3.21.0-0.3.el6_7.x86_64.rpm

Source:
ae57322f9c969f39ae79298247a6a8a795719d1e926d88077a92536b8332409c nss-3.21.0-0.3.el6_7.src.rpm

i386:
be545dfd2d5da2c62a77f9cc2b40987befdb5c5f669782af9c377f0b85484ff0 nss-util-3.21.0-0.3.el6_7.i686.rpm
56806dccf241355a1b9cba4e1595f54abbe5a5b1f92b9a4d4f5b7d8091bc7325 nss-util-devel-3.21.0-0.3.el6_7.i686.rpm

x86_64:
be545dfd2d5da2c62a77f9cc2b40987befdb5c5f669782af9c377f0b85484ff0 nss-util-3.21.0-0.3.el6_7.i686.rpm
a7241304459acb2e2dca19fa7a61f516f2a38aa3e4440d1a2f001de413c54e1f nss-util-3.21.0-0.3.el6_7.x86_64.rpm
56806dccf241355a1b9cba4e1595f54abbe5a5b1f92b9a4d4f5b7d8091bc7325 nss-util-devel-3.21.0-0.3.el6_7.i686.rpm
7cb08f5c7d2c44566206fc7fb5c9dcb380b9ec3e036eecf3bc99ec764e95043e nss-util-devel-3.21.0-0.3.el6_7.x86_64.rpm

Source:
3c391ab73bc502dc1a1aa74a1aeda1ddf08aee80c85ed02396808117d1a89ce5 nss-util-3.21.0-0.3.el6_7.src.rpm

Cause:   Access control error, Input validation error
Underlying OS:  Linux (CentOS)
Underlying OS Comments:  6

Message History:   This archive entry is a follow-up to the message listed below.
Mar 9 2016 Mozilla Firefox Multiple Flaws Let Remote Users Execute Arbitrary Code, Spoof the Address Bar, Overwrite Files, and Deny Service



 Source Message Contents

Subject:  [CentOS-announce] CESA-2016:0591 Moderate CentOS 6 nss Security Update


CentOS Errata and Security Advisory 2016:0591 Moderate

Upstream details at : https://rhn.redhat.com/errata/RHSA-2016-0591.html

The following updated files have been uploaded and are currently 
syncing to the mirrors: ( sha256sum Filename ) 

i386:
5c8974b2d8730e2967751f835f4646bdf46fa968c29769748219ad426c5140d3  nss-3.21.0-0.3.el6_7.i686.rpm
f3782c46dfadef016d7afe8d81015c92ca5062e738d225377bfb38904e70708d  nss-devel-3.21.0-0.3.el6_7.i686.rpm
32b9c62453b3dd45c60985751e36ed30aba93ea2f024b4b08443b7b9438eb5a8  nss-pkcs11-devel-3.21.0-0.3.el6_7.i686.rpm
7ee7fb2e4107b38d7c03677abb588fdd59b28459fa01a67f1a0bfb159295c688  nss-sysinit-3.21.0-0.3.el6_7.i686.rpm
a24d41eaadacaebcab9e7bf5490dc75028d7360e8484d9f4615b480067299539  nss-tools-3.21.0-0.3.el6_7.i686.rpm

x86_64:
5c8974b2d8730e2967751f835f4646bdf46fa968c29769748219ad426c5140d3  nss-3.21.0-0.3.el6_7.i686.rpm
7242d7e199b316736c10a1e97629001a3f2ab4ba540f0e313730ae8a11358544  nss-3.21.0-0.3.el6_7.x86_64.rpm
f3782c46dfadef016d7afe8d81015c92ca5062e738d225377bfb38904e70708d  nss-devel-3.21.0-0.3.el6_7.i686.rpm
24a8bfae413d2a0ea8063fe0045615096d0cff4e8ddb483b625f32a20c403fb4  nss-devel-3.21.0-0.3.el6_7.x86_64.rpm
32b9c62453b3dd45c60985751e36ed30aba93ea2f024b4b08443b7b9438eb5a8  nss-pkcs11-devel-3.21.0-0.3.el6_7.i686.rpm
dc1976aceb5f1e49dcb95308bc6ae80e9100d759141308f5fb786ac6d49e65b3  nss-pkcs11-devel-3.21.0-0.3.el6_7.x86_64.rpm
99a95ba3bfebf8d62f4033b0578ff4c0a604becc5e5255700d98ccf305e68cc9  nss-sysinit-3.21.0-0.3.el6_7.x86_64.rpm
f1af7ca96a93c1ebeeab8051f137e92116d869ba0aa55c28bf7a6d0bcf7b49e7  nss-tools-3.21.0-0.3.el6_7.x86_64.rpm

Source:
ae57322f9c969f39ae79298247a6a8a795719d1e926d88077a92536b8332409c  nss-3.21.0-0.3.el6_7.src.rpm



-- 
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
Twitter: @JohnnyCentOS

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce
 
 


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us

This web site uses cookies for web analytics. Learn More

Copyright 2021, SecurityGlobal.net LLC